
CVE-2026-74251
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3
database-securitydata-exfiltrationexploitation+3

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

Remote attacker can access sensitive data exposed on the URL